🟠 High  |  Source: The Hacker News


Researchers from Nanyang Technological University have disclosed 84 security vulnerabilities across 4G and 5G core network implementations, including flaws that enable denial-of-service attacks and session hijacking. These weaknesses affect the foundational control-plane components that manage user connectivity and authentication. The findings are significant because mobile core networks underpin connectivity for enterprise cloud workloads, IoT devices, and critical infrastructure.

Security Architect’s Take: If your organisation relies on private 5G networks, SD-WAN with cellular failover, or mobile-connected edge infrastructure, engage your telco and network equipment vendors to confirm which core implementations are affected and request patch timelines. Additionally, review whether session-layer controls such as mutual TLS and zero-trust network access policies are in place to limit the blast radius of any session hijacking attempt.

Original advisory: Researchers Report 84 Flaws in 4G and 5G Cores, Including a Session Hijacking Flaw